1
00:00:06,480 --> 00:00:09,210
- In this lesson we're gonna
focus in on virtualization.

2
00:00:09,210 --> 00:00:11,220
I know I've introduced
virtualization to you a couple

3
00:00:11,220 --> 00:00:13,050
of times, but this time we get to spend

4
00:00:13,050 --> 00:00:15,663
an entire lesson on virtualization.

5
00:00:16,650 --> 00:00:18,750
Now virtualization is a
technology that creates

6
00:00:18,750 --> 00:00:21,150
multiple environments from a single

7
00:00:21,150 --> 00:00:23,010
physical hardware system.

8
00:00:23,010 --> 00:00:26,550
So take one big powerful
host, and we can divide it up

9
00:00:26,550 --> 00:00:29,430
into multiple environments.

10
00:00:29,430 --> 00:00:32,400
Now most of us think of
virtualization as a virtual server

11
00:00:32,400 --> 00:00:35,370
or a virtual machine,
but there's really a lot

12
00:00:35,370 --> 00:00:37,533
of different aspects to virtualization.

13
00:00:39,390 --> 00:00:41,520
Let's talk about the benefits
first before we talk about

14
00:00:41,520 --> 00:00:42,810
the different types.

15
00:00:42,810 --> 00:00:45,120
Each virtual instance is going to behave

16
00:00:45,120 --> 00:00:48,060
as if it were a physically
separate system,

17
00:00:48,060 --> 00:00:51,360
but it's really running
on a shared physical host.

18
00:00:51,360 --> 00:00:54,000
So a major benefit of virtualization

19
00:00:54,000 --> 00:00:55,863
is resource utilization.

20
00:00:56,760 --> 00:00:59,550
Virtualization enables the
efficient use of hardware

21
00:00:59,550 --> 00:01:02,700
resources, again by allowing
multiple virtual systems

22
00:01:02,700 --> 00:01:05,250
to run on that single physical system.

23
00:01:05,250 --> 00:01:07,980
The benefit, it can improve
resource utilization

24
00:01:07,980 --> 00:01:10,290
and reduce cost.

25
00:01:10,290 --> 00:01:12,900
And then we have flexibility,
because virtualization

26
00:01:12,900 --> 00:01:15,450
provides flexibility
and scalability, right?

27
00:01:15,450 --> 00:01:18,390
That ability to grow, by
allowing virtual systems

28
00:01:18,390 --> 00:01:21,720
to be easily created,
deployed, and managed

29
00:01:21,720 --> 00:01:26,310
without the need to invest in
additional physical hardware.

30
00:01:26,310 --> 00:01:28,470
So resource utilization and flexibility

31
00:01:28,470 --> 00:01:31,083
two major benefits of virtualization.

32
00:01:32,040 --> 00:01:33,930
Now there's different
types of virtualization,

33
00:01:33,930 --> 00:01:35,700
we have server virtualization,

34
00:01:35,700 --> 00:01:37,590
where have multiple
virtual servers referred to

35
00:01:37,590 --> 00:01:40,830
as virtual machines on
a single physical host,

36
00:01:40,830 --> 00:01:43,740
we can have virtual desktops
that can be accessed

37
00:01:43,740 --> 00:01:46,530
by our users, we can have virtual storage

38
00:01:46,530 --> 00:01:49,200
pulling in multiple storage
devices into a single

39
00:01:49,200 --> 00:01:52,110
virtual storage system,
and we can have network

40
00:01:52,110 --> 00:01:55,120
virtualization creating virtual
networks without requiring

41
00:01:55,120 --> 00:01:57,390
physical network hardware.

42
00:01:57,390 --> 00:01:59,280
So let's dive deeper
into each one of these;

43
00:01:59,280 --> 00:02:03,093
server, desktop, storage, and network.

44
00:02:04,530 --> 00:02:06,870
Server virtualization allows the resources

45
00:02:06,870 --> 00:02:08,280
of the host, right?

46
00:02:08,280 --> 00:02:10,650
To guest servers, which
we refer to generally

47
00:02:10,650 --> 00:02:13,140
as virtual machines, we
talked about having a host

48
00:02:13,140 --> 00:02:15,960
and having VMs, or virtual machines.

49
00:02:15,960 --> 00:02:18,630
Now the physical host
computer has the processor,

50
00:02:18,630 --> 00:02:21,090
the memory, the storage,
the networking components,

51
00:02:21,090 --> 00:02:23,070
and we're gonna use specialized software

52
00:02:23,070 --> 00:02:26,220
to dynamically allocate those resources.

53
00:02:26,220 --> 00:02:29,190
Now virtual machines are gonna act exactly

54
00:02:29,190 --> 00:02:31,050
like physical machines, right?

55
00:02:31,050 --> 00:02:33,330
They each have an
independent operating system,

56
00:02:33,330 --> 00:02:34,950
they're gonna have their own applications,

57
00:02:34,950 --> 00:02:36,870
they'll have their own
network connections,

58
00:02:36,870 --> 00:02:39,390
and they're going to use
the resources, right?

59
00:02:39,390 --> 00:02:41,430
That have been allocated to them.

60
00:02:41,430 --> 00:02:42,780
But that's important to think about,

61
00:02:42,780 --> 00:02:45,990
that they behave like a physical machine,

62
00:02:45,990 --> 00:02:48,660
because that means that things like

63
00:02:48,660 --> 00:02:51,540
configuration management,
change management,

64
00:02:51,540 --> 00:02:55,380
patch management, you
know, doing assessments,

65
00:02:55,380 --> 00:02:58,680
vulnerability management,
audit, licensing,

66
00:02:58,680 --> 00:03:00,510
they all have to be thought of in terms

67
00:03:00,510 --> 00:03:02,343
of each virtual machine.

68
00:03:05,220 --> 00:03:07,260
Now hypervisors are gonna be the software

69
00:03:07,260 --> 00:03:08,940
or firmware components we actually use

70
00:03:08,940 --> 00:03:12,870
to virtualize the system
resources on a host system

71
00:03:12,870 --> 00:03:14,400
to have our virtual machines.

72
00:03:14,400 --> 00:03:16,587
And there are two types of hypervisors,

73
00:03:16,587 --> 00:03:18,570
you have a type one and type two.

74
00:03:18,570 --> 00:03:21,030
A type one, sometimes
referred to as a bare metal,

75
00:03:21,030 --> 00:03:24,420
or a native hypervisor, run
directly on the system hardware.

76
00:03:24,420 --> 00:03:27,360
They have direct access to
the hardware, and so we don't

77
00:03:27,360 --> 00:03:30,000
need an operating system
to load, as the hypervisor

78
00:03:30,000 --> 00:03:32,280
is really the operating system.

79
00:03:32,280 --> 00:03:34,530
In a type two hypervisor,
sometimes referred to

80
00:03:34,530 --> 00:03:37,860
as hosted, is hypervisors
that specialized software

81
00:03:37,860 --> 00:03:40,200
is running on a host operating system

82
00:03:40,200 --> 00:03:43,020
that provides the virtualization services.

83
00:03:43,020 --> 00:03:46,590
Now type one is going to be
faster and more efficient,

84
00:03:46,590 --> 00:03:49,950
but it has greater hardware
requirements and expense

85
00:03:49,950 --> 00:03:50,913
than type two.

86
00:03:53,610 --> 00:03:55,740
We talked about containers
not once, not twice,

87
00:03:55,740 --> 00:03:57,330
this might be our third time.

88
00:03:57,330 --> 00:03:59,250
This is a refresher,
containers are products

89
00:03:59,250 --> 00:04:01,440
of an operating system virtualization,

90
00:04:01,440 --> 00:04:03,450
we don't need a hypervisor.

91
00:04:03,450 --> 00:04:05,940
Containers provide a
lightweight virtual environment

92
00:04:05,940 --> 00:04:09,120
referred to as an instance,
our operating system containers

93
00:04:09,120 --> 00:04:11,190
are virtual environments
that share the kernel

94
00:04:11,190 --> 00:04:14,280
of a host operating system,
but can provide user space

95
00:04:14,280 --> 00:04:16,920
isolation, where our
application containers

96
00:04:16,920 --> 00:04:19,500
are virtual environments
that share the kernel

97
00:04:19,500 --> 00:04:22,620
of the host operating
system designed to package

98
00:04:22,620 --> 00:04:24,603
and run a single service.

99
00:04:28,110 --> 00:04:30,840
So moving away from virtual machines,

100
00:04:30,840 --> 00:04:33,180
let's talk about desktop virtualization.

101
00:04:33,180 --> 00:04:35,640
The virtual desktop
infrastructure, I'm gonna refer to

102
00:04:35,640 --> 00:04:38,910
just as VDI, is virtualization technology

103
00:04:38,910 --> 00:04:41,760
that hosts a desktop operating system

104
00:04:41,760 --> 00:04:44,403
on a centralized server,
in the data center.

105
00:04:45,720 --> 00:04:48,570
Now there are two types
of desktop virtualization;

106
00:04:48,570 --> 00:04:51,180
persistent and non-persistent.

107
00:04:51,180 --> 00:04:54,480
A persistent VDI, a virtual
desktop infrastructure,

108
00:04:54,480 --> 00:04:58,320
provides each user with his
or her own desktop image,

109
00:04:58,320 --> 00:05:01,020
which can be customized
and saved for future uses,

110
00:05:01,020 --> 00:05:03,570
very much like a traditional desktop.

111
00:05:03,570 --> 00:05:08,010
Non-persistent VDI provides
this pool of uniform desktops

112
00:05:08,010 --> 00:05:10,650
that users can access
whenever they need it,

113
00:05:10,650 --> 00:05:13,140
but non-persistent
desktops revert right back

114
00:05:13,140 --> 00:05:16,050
to their original state
each time the user logs out,

115
00:05:16,050 --> 00:05:17,760
so it doesn't matter what
the user might have saved

116
00:05:17,760 --> 00:05:20,010
on the desktop or what
configuration changes

117
00:05:20,010 --> 00:05:22,140
they might have made,
that all gets wiped out

118
00:05:22,140 --> 00:05:24,720
and we're back to the
original state each time

119
00:05:24,720 --> 00:05:25,863
the user logs out.

120
00:05:27,990 --> 00:05:30,900
Then we have network
virtualization, or NSX.

121
00:05:30,900 --> 00:05:33,420
Network virtualization is
a complete reproduction

122
00:05:33,420 --> 00:05:35,590
of a physical network in software,

123
00:05:35,590 --> 00:05:38,340
which is hard to imagine, isn't it?

124
00:05:38,340 --> 00:05:41,310
The network virtualization
presents logical networking

125
00:05:41,310 --> 00:05:44,100
devices and services, like
logical ports, switches,

126
00:05:44,100 --> 00:05:47,970
routers, firewalls, load
balancers, even VPNs.

127
00:05:47,970 --> 00:05:50,970
Virtual networks offer the
same features and guarantees

128
00:05:50,970 --> 00:05:53,760
of a physical network with
the operational benefits

129
00:05:53,760 --> 00:05:56,523
of hardware independence
of virtualization.

130
00:05:57,750 --> 00:06:01,530
So do we have any security
concerns about virtualization?

131
00:06:01,530 --> 00:06:03,240
Well, two in particular;

132
00:06:03,240 --> 00:06:06,843
virtual machine escape,
and virtualization sprawl.

133
00:06:07,830 --> 00:06:11,130
Virtual machine escape
happens when a virtual machine

134
00:06:11,130 --> 00:06:14,430
and the host operating system interact,

135
00:06:14,430 --> 00:06:17,160
that should never,
ever, ever, ever happen.

136
00:06:17,160 --> 00:06:19,890
But over time multiple
exploitable vulnerabilities

137
00:06:19,890 --> 00:06:23,730
have been identified, which
means that it's really important

138
00:06:23,730 --> 00:06:25,830
that your virtual machine hosts

139
00:06:25,830 --> 00:06:27,480
are going to be included, right?

140
00:06:27,480 --> 00:06:30,120
Your virtualization host,
are gonna be included

141
00:06:30,120 --> 00:06:32,130
in your organizational vulnerability

142
00:06:32,130 --> 00:06:34,650
and patch management programs.

143
00:06:34,650 --> 00:06:37,350
The second is virtualization sprawl.

144
00:06:37,350 --> 00:06:39,990
Now virtualization sprawl
occurs when the number

145
00:06:39,990 --> 00:06:43,170
of virtual systems is like,
out of control, right?

146
00:06:43,170 --> 00:06:45,510
Potentially unmanaged, unnecessary,

147
00:06:45,510 --> 00:06:48,030
and not in compliance
with licensing agreements.

148
00:06:48,030 --> 00:06:50,430
And we talked about virtualization sprawl

149
00:06:50,430 --> 00:06:54,330
way back when we talked about
some operational issues.

150
00:06:54,330 --> 00:06:55,680
So here's the way to think about it.

151
00:06:55,680 --> 00:06:57,690
Our virtual devices
should always be treated

152
00:06:57,690 --> 00:06:59,520
the same as our physical systems.

153
00:06:59,520 --> 00:07:03,180
And subject to asset
management, capacity management,

154
00:07:03,180 --> 00:07:06,180
configuration management,
vulnerability management,

155
00:07:06,180 --> 00:07:09,300
licensing, assessment, and audit.

156
00:07:09,300 --> 00:07:11,190
Just because they're a
virtual device doesn't mean

157
00:07:11,190 --> 00:07:13,890
that they should be
excluded from any of those.

158
00:07:13,890 --> 00:07:16,800
So we wanna make sure that
we're always managing them,

159
00:07:16,800 --> 00:07:18,930
that we understand their necessity,

160
00:07:18,930 --> 00:07:21,080
and that we have the
appropriate licensing.

161
00:07:24,060 --> 00:07:26,820
And that my friends bring us
to a three second challenge.

162
00:07:26,820 --> 00:07:28,500
Our challenge question's
three seconds each,

163
00:07:28,500 --> 00:07:29,333
let's do it.

164
00:07:30,360 --> 00:07:32,700
Software or firmware
components that can virtualize

165
00:07:32,700 --> 00:07:33,903
system resources?

166
00:07:35,070 --> 00:07:37,353
One, two, three.

167
00:07:38,910 --> 00:07:40,360
That's gonna be a hypervisor.

168
00:07:41,670 --> 00:07:44,070
Number two; term applied to an environment

169
00:07:44,070 --> 00:07:48,060
where the number of virtual
machines is out of control.

170
00:07:48,060 --> 00:07:49,800
That's the one we just talked about.

171
00:07:49,800 --> 00:07:51,243
One, two, three.

172
00:07:52,560 --> 00:07:54,303
That's virtualization sprawl.

173
00:07:55,710 --> 00:07:59,520
Number three; this type of VDI, right?

174
00:07:59,520 --> 00:08:03,210
So virtual desktop, reverts
back to its original state

175
00:08:03,210 --> 00:08:05,043
each time the user logs out.

176
00:08:06,750 --> 00:08:08,643
One, two, three.

177
00:08:09,720 --> 00:08:11,880
That's gonna be a non-persistent VDI.

178
00:08:11,880 --> 00:08:16,050
Remember we had a persistent
VDI and a non-persistent VDI.

179
00:08:16,050 --> 00:08:19,200
Number four; the term
applied to a situation

180
00:08:19,200 --> 00:08:21,480
where a virtual machine and a host

181
00:08:21,480 --> 00:08:23,730
operating system interact.

182
00:08:23,730 --> 00:08:26,193
We said this should
never, ever, ever happen.

183
00:08:27,180 --> 00:08:29,670
Okay, we wanna make sure
we're always patching, right?

184
00:08:29,670 --> 00:08:32,310
Our systems to make sure it never happens.

185
00:08:32,310 --> 00:08:34,410
One, two, three.

186
00:08:34,410 --> 00:08:37,290
That's known as virtual machine escape.

187
00:08:37,290 --> 00:08:41,010
Lastly, number five; a
lightweight virtual environment,

188
00:08:41,010 --> 00:08:43,410
also called instances,
that we've now talked about

189
00:08:43,410 --> 00:08:44,760
multiple times.

190
00:08:44,760 --> 00:08:47,940
One, two, three, I know
you're gonna get it.

191
00:08:47,940 --> 00:08:49,470
And that's a container.

192
00:08:49,470 --> 00:08:50,730
All right, good work.

193
00:08:50,730 --> 00:08:52,950
Let's move into a security in action.

194
00:08:52,950 --> 00:08:55,890
This one is about VM sprawl.

195
00:08:55,890 --> 00:08:59,250
So your organization has
enthusiastically adopted

196
00:08:59,250 --> 00:09:01,710
virtualization, you
virtualized your servers,

197
00:09:01,710 --> 00:09:03,990
networks, even your desktops.

198
00:09:03,990 --> 00:09:08,400
Your CIO has instructed the
IT team to spin up a server

199
00:09:08,400 --> 00:09:11,850
for every application,
for almost every service.

200
00:09:11,850 --> 00:09:14,820
Performance is great, users are happy,

201
00:09:14,820 --> 00:09:18,600
expenses are within budget,
so what could go wrong?

202
00:09:18,600 --> 00:09:20,790
Well you have a concern.

203
00:09:20,790 --> 00:09:23,520
You express concerns about the impact

204
00:09:23,520 --> 00:09:26,973
of VM, virtual machine
sprawl, to your manager.

205
00:09:28,620 --> 00:09:31,560
After she sighs, says,
"Yeah, but users are happy,

206
00:09:31,560 --> 00:09:34,560
performance is great,
expenses are within budget."

207
00:09:34,560 --> 00:09:37,770
She says, "Okay, document your concerns,

208
00:09:37,770 --> 00:09:39,660
and then we'll have a conversation."

209
00:09:39,660 --> 00:09:42,180
So what might you include on the list?

210
00:09:42,180 --> 00:09:44,760
So go ahead and put me
on pause, write about

211
00:09:44,760 --> 00:09:47,970
your concerns about VM
sprawl, how are we gonna talk

212
00:09:47,970 --> 00:09:49,053
to this manager?

213
00:09:52,170 --> 00:09:56,010
Well, what you may say is,
"Listen, when we spin up

214
00:09:56,010 --> 00:09:59,040
a server for everything,
and we have these desktops,

215
00:09:59,040 --> 00:10:00,420
and networks, right?

216
00:10:00,420 --> 00:10:03,000
We have too many machines, potentially,

217
00:10:03,000 --> 00:10:06,960
too many devices, to manage effectively.

218
00:10:06,960 --> 00:10:09,750
We're adding to our vulnerability
and patch management

219
00:10:09,750 --> 00:10:13,470
overhead every time we
spin up a new machine.

220
00:10:13,470 --> 00:10:16,350
We may not be in licensing compliance.

221
00:10:16,350 --> 00:10:19,020
Do we have enough licenses
for our operating systems?

222
00:10:19,020 --> 00:10:20,583
For our applications?

223
00:10:22,080 --> 00:10:24,210
And, you know, we may have unnecessary

224
00:10:24,210 --> 00:10:26,970
resource consumptions,
it may not be necessary

225
00:10:26,970 --> 00:10:30,300
to be spinning up a server
for every single application.

226
00:10:30,300 --> 00:10:33,300
We really need to have a good plan,

227
00:10:33,300 --> 00:10:36,180
and we need to recognize
that each one of those

228
00:10:36,180 --> 00:10:39,840
virtual devices have to
be managed as if they were

229
00:10:39,840 --> 00:10:44,010
a physical device, and if we're
good with that, that's okay.

230
00:10:44,010 --> 00:10:46,170
As long as we've recognized that, right?

231
00:10:46,170 --> 00:10:48,090
And we understand what we need to do,

232
00:10:48,090 --> 00:10:51,330
and we understand the
resources we have to devote.

233
00:10:51,330 --> 00:10:54,810
But we can't just think of
virtualization as this panacea

234
00:10:54,810 --> 00:10:56,940
without any consequences.

235
00:10:56,940 --> 00:10:58,200
And that's the conversation

236
00:10:58,200 --> 00:10:59,950
that you should probably be having.

237
00:11:01,440 --> 00:11:03,300
Right, that takes us to our word cloud,

238
00:11:03,300 --> 00:11:04,590
you know what to do.

239
00:11:04,590 --> 00:11:06,630
When you're ready, come on
over to the next lesson,

240
00:11:06,630 --> 00:11:08,130
I'll be waiting for you there.
